The Comptroller of Puerto Rico issues a qualified opinion on, among other things, the controls for the administration of security, logical access, and the processing of data of the Agricultural Insurance Program Application System (SAPSSA) of the Office of Information Systems of the Corporación de Seguros Agrícolas de Puerto Rico. A qualified opinion is issued when the instances of noncompliance, individually or together, are significant but not pervasive.
The Report reveals that as of April 27, 2016, the Corporation had not prepared the risk analysis report of the computerized information systems. This situation prevents the Corporation from estimating the impact that the risk elements would have on critical areas and systems.
The Corporation did not have a business continuity plan, nor a contingency plan, nor an alternate center for the recovery of the information systems in case of emergency. The continuity plan is necessary to achieve the prompt operation of the systems and restore operations in case of risks such as voltage variations, computer viruses, malicious attacks, or natural disasters. The contingency plan is a guide that guarantees the continuity of the normal operations of the information systems when unexpected situations arise that affect their functioning.
The seven-finding audit notes that, contrary to what is required in the Information Systems Manual approved by the executive director in 2015, weekly, monthly, and annual backups were not performed, nor were the five backup generations maintained. In addition, backups were not kept outside the Corporation's Central Office. This situation may cause that, in cases of emergency, the information backups cannot be available for the continuity of operations, as occurred in 2015 when the Corporation had to acquire technical services for $40,691 to recover the SAPSSA data.
Our auditors identified multiple deficiencies in the password parameters for the access accounts, the maintenance of the SAPSSA accounts, and the SAPSSA quality module. For example, the Corporation had 23 accounts that did not expire, and 15 configured so that they would not be changed. In addition, disused accounts had been deactivated up to six years later, three former employees used their access accounts up to two years after their separation from employment, and the Quality Control module did not function properly.
The Report covers the period from January 19 to December 15, 2016.
See Audit Report TI-18-13.
To view other published reports, visit our Audit Reports section.
Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.